Search CVE reports
171 – 180 of 48426 results
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
1 affected package
python-tornado
| Package | 16.04 LTS |
|---|---|
| python-tornado | Needs evaluation |
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
1 affected package
sudo
| Package | 16.04 LTS |
|---|---|
| sudo | Not affected |
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...
1 affected package
ruby-rack
| Package | 16.04 LTS |
|---|---|
| ruby-rack | Needs evaluation |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...
1 affected package
ruby-rack
| Package | 16.04 LTS |
|---|---|
| ruby-rack | Needs evaluation |
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling...
1 affected package
ruby-rack
| Package | 16.04 LTS |
|---|---|
| ruby-rack | Needs evaluation |
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack...
1 affected package
ruby-rack
| Package | 16.04 LTS |
|---|---|
| ruby-rack | Needs evaluation |
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
2 affected packages
openssh, openssh-ssh1
| Package | 16.04 LTS |
|---|---|
| openssh | Needs evaluation |
| openssh-ssh1 | — |